AWS Certified Security - Specialty

AWS · SCS-C03 · Specialty

AWS · AWS Ecosystem

AWS Certified Security - Specialty

SCS-C03activeSpecialty
Official AWS source · aws.amazon.com

SCS-C03 · ● Active · Specialty · AWS

Launched: December 2, 2025
Previous version (SCS-C02): Retiring December 1, 2025
Delivery: Pearson VUE (OnVUE remote + testing center)


Exam facts

FieldValue
Cost$300 USD
Duration170 minutes
Questions65 (50 scored, 15 unscored pilot questions)
Passing750/1000 (scaled score)
FormatMultiple choice, multiple response, scenario-based, ordering, matching
DeliveryPearson VUE (OnVUE remote and testing centers)
LanguagesEnglish, Japanese, Korean, Simplified Chinese, Traditional Chinese
Valid3 years
RenewalPass a higher-level AWS cert (SAP-C02) or retake SCS-C03
PrerequisitesNone official; AWS Certified Solutions Architect – Associate (SAA-C03) recommended
ReleasedDecember 2, 2025
RetiringSCS-C02 retired December 1, 2025

Vendor source — AWS Certified Security – Specialty ↗

Official exam guide — AWS Certified Security – Specialty (SCS-C03) Exam Guide PDF ↗

Exam objectives — AWS Certified Security – Specialty (SCS-C03) Documentation ↗


About

AWS Certified Security — Specialty (SCS-C03) validates expertise in designing, implementing, and managing secure AWS workloads. Launched December 2, 2025, SCS-C03 replaces SCS-C02 and introduces new coverage of AI/ML security, modern threat-detection tools, and zero-trust architecture principles. Designed for security professionals with 1–2+ years of hands-on AWS security experience, it targets cloud security engineers, architects, and DevSecOps practitioners. Unlike the Associate-level SAA-C03, this is a specialty-level cert — deeper, narrower, and assumes foundational AWS knowledge.


Domain context — Cloud Security

Public cloud security across hyperscale providers (AWS, Azure, GCP, OCI) — securing data, infrastructure, identity, and operations in cloud-native environments. This certification is AWS-specific within the broader Cloud Security domain.


Topics covered

Content Domain 1: Detection (16% of scored content)

  • CloudWatch Logs and metrics configuration
  • AWS CloudTrail and VPC Flow Logs for forensics
  • Amazon GuardDuty threat detection
  • Amazon Macie for data discovery and protection
  • Security Hub for aggregated monitoring
  • EventBridge for automated alerting

Content Domain 2: Incident Response (14% of scored content)

  • Incident response playbooks and automation
  • AWS Systems Manager Session Manager for forensic access
  • VPC isolation and network segmentation for containment
  • Snapshot isolation and AMI backup strategies
  • Post-incident analysis and root-cause investigation
  • Third-party SIEM/SOAR integration

Content Domain 3: Infrastructure Security (18% of scored content)

  • VPC design, security groups, and network ACLs
  • AWS PrivateLink and VPC endpoints
  • Amazon WAF and Shield for DDoS/web-layer protection
  • EC2 hardening: IMDSv2, Nitro attestation, encrypted volumes
  • Container security: ECR image scanning, ECS task security
  • Lambda security: execution roles, function-level isolation

Content Domain 4: Identity and Access Management (20% of scored content)

  • IAM policy design and least-privilege patterns
  • Cross-account access and AWS Organizations
  • AWS SSO / Identity Center federation
  • SAML, OIDC, and external IdP integration
  • Temporary credentials and STS assume-role workflows
  • Permission boundaries and service control policies (SCPs)

Content Domain 5: Data Protection (18% of scored content)

  • Server-side encryption (S3, EBS, RDS, DynamoDB)
  • AWS KMS key management and rotation
  • Client-side encryption and AWS Encryption SDK
  • Secrets Manager and Parameter Store for credential rotation
  • Database-level encryption (TDE, transparent data encryption)
  • Data classification and DLP (Macie)

Content Domain 6: Security Foundations and Governance (14% of scored content)

  • Security best practices and AWS Well-Architected Framework (Security Pillar)
  • Compliance frameworks (PCI-DSS, HIPAA, SOC 2, GDPR, FedRAMP)
  • AWS Config for compliance automation
  • Cost-security tradeoffs in architecture
  • AI/ML security (new in SCS-C03)

Source: AWS Certified Security – Specialty (SCS-C03) Exam Guide PDF ↗


Common skills at Cloud Security · Specialty

Shared competencies for the Cloud Security domain at Specialty level — not specific to this cert.

  • Defense-in-depth architecture across identity, data, network, and application layers
  • Threat modeling and risk assessment in cloud-native environments
  • Compliance automation and audit-trail design
  • Cloud-native incident response and forensic investigation
  • Zero-trust architecture principles
  • Cost-security tradeoff decisions at scale
  • Third-party integration (SIEM, SOAR, vulnerability scanners)
  • Encryption key lifecycle management

Recommended courses at Security · Professional

ProviderTitleCostURL
AWS Skill BuilderAWS Certified Security – Specialty (SCS-C03) Exam PrepFree tier + Premium
AWS Skill BuilderOfficial Pretest: SCS-C03Free
Udemy (Stephane Maarek)Ultimate AWS Certified Security Specialty [NEW 2026] SCS-C03$15–$99
Tutorials DojoAWS Certified Security Specialty SCS-C03 Video Course$29–$99
PluralsightAWS Certified Security – Specialty (SCS-C03)$299/yr or $29/mo
A Cloud Guru (Pluralsight)AWS Certified Security Specialty (SCS-C03)$299/yr

Course-selection rule: Stephane Maarek's Udemy course is the most cost-effective, exam-focused option (100% updated for SCS-C03 in January 2026). AWS Skill Builder is the official option with free-tier access. Tutorials Dojo offers detailed video explanations. Adrian Cantrill's course is not yet released for SCS-C03.


Practice exams

ProviderTitleCostURL
Tutorials DojoAWS Certified Security Specialty Practice Exams SCS-C03$19–$39
Tutorials DojoStudy Guide eBook – AWS Certified Security Specialty SCS-C03$12–$19
ExamCertSCS-C03 Free Practice Test (500+ questions)Free
AWS Skill BuilderOfficial SCS-C03 Practice Exam (Pearson)Free with subscription

Practice exam quality: Tutorials Dojo practice exams are widely recognized as the closest match to actual AWS exam difficulty and tone. Their 4-mode testing (timed, review, section-based, final) allows targeted review. ExamCert and Whizlabs also offer free-tier samples for trial runs.


Books

TitleAuthorPublisherYearISBNURL
AWS Certified Security Study Guide: Specialty (SCS-C02) Exam, 2nd EditionMauricio Muñoz, Dario Lucas Goldfarb, Alexandre M. S. P. Moraes, Omner Barajas, Andres Gonzalez-Santos, Rogerio KasaSybex (Wiley)2024978-1394253463

Book note: As of May 2026, no SCS-C03-specific study guide has been published. The Sybex 2nd Edition (2024) covers the SCS-C02 exam — the immediate predecessor to SCS-C03. It remains relevant for foundational security concepts but does not cover new SCS-C03 domains (AI/ML security, modern threat tools). Use it as a supplement only, paired with AWS Skill Builder SCS-C03 practice materials. Watch Wiley/Sybex for a dedicated SCS-C03 edition.


Typical job titles at Cloud Security · Specialty

AWS Cloud Security Engineer · AWS Security Architect · Senior Security Engineer (AWS focus) · Cloud Security Specialist · AWS Security Consultant · Infrastructure Security Engineer

(Job titles drawn from current job-board postings that list SCS-C03 or AWS security expertise as required or preferred.)


Salary

Salary note: AWS-certified security roles command premium compensation due to scarcity of specialized cloud security expertise. Salaries vary significantly by experience level (3–5 years junior, 8+ years senior), company size (startups vs. FAANG), and location (major tech hubs command 20–40% higher rates). South African and UK figures reflect local market conditions; AWS security expertise is in high global demand.


Skills validated

Technologies and practices this exam specifically tests.

  • AWS CloudTrail, CloudWatch, VPC Flow Logs (logging)
  • Amazon GuardDuty, Macie, Security Hub (threat detection)
  • AWS Systems Manager, Session Manager (incident response)
  • VPC design, security groups, network ACLs, PrivateLink
  • AWS WAF, Shield, DDoS protection
  • EC2 security: IMDSv2, Nitro attestation, encrypted volumes
  • Container security: ECR, ECS, Lambda function isolation
  • IAM policy design, permission boundaries, SCPs
  • AWS SSO / Identity Center, SAML, OIDC
  • AWS KMS, Secrets Manager, Parameter Store, Encryption SDK
  • AWS Config, Service Control Policies (SCPs)
  • Compliance frameworks (PCI-DSS, HIPAA, SOC 2, GDPR, FedRAMP)
  • Cost-security tradeoff analysis
  • AI/ML security workloads (new in SCS-C03)

Related certifications


Sources


Last verified: 2026-05-01 Domain: Cloud Security Ecosystem: AWS Ecosystem Vendor: AWS


Roles that use this certification

1 career-path guide on this site put this exam in the sequence.

Rate this cert
Was this helpful?
Comments ()
0/2000